Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
30224
Total
2398
Critical
9069
High
9411
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-35455 | HIGH | 7.3 | immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any … | Apr 08, 2026 |
| CVE-2026-35446 | HIGH | 7.7 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-35407 | UNKNOWN | — | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email … | Apr 08, 2026 |
| CVE-2026-35403 | MEDIUM | 6.5 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-35401 | HIGH | 7.5 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in … | Apr 08, 2026 |
| CVE-2026-35400 | LOW | 3.5 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-35169 | HIGH | 8.7 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and … | Apr 08, 2026 |
| CVE-2026-35165 | MEDIUM | 6.3 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-34985 | MEDIUM | 6.3 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-34837 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., … | Apr 08, 2026 |
| CVE-2026-34782 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a … | Apr 08, 2026 |
| CVE-2026-34724 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent … | Apr 08, 2026 |
| CVE-2026-34723 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started … | Apr 08, 2026 |
| CVE-2026-34722 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if … | Apr 08, 2026 |
| CVE-2026-34721 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external … | Apr 08, 2026 |
| CVE-2026-34720 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header … | Apr 08, 2026 |
| CVE-2026-34719 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop … | Apr 08, 2026 |
| CVE-2026-34718 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization … | Apr 08, 2026 |
| CVE-2026-34392 | HIGH | 7.5 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 … | Apr 08, 2026 |
| CVE-2026-34248 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could … | Apr 08, 2026 |
| CVE-2026-34166 | LOW | 3.7 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory … | Apr 08, 2026 |
| CVE-2026-33350 | HIGH | 7.5 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, … | Apr 08, 2026 |
| CVE-2026-30818 | UNKNOWN | — | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a … | Apr 08, 2026 |
| CVE-2026-30817 | UNKNOWN | — | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious … | Apr 08, 2026 |
| CVE-2026-30816 | UNKNOWN | — | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a … | Apr 08, 2026 |